CVE-2026-55628: ImageMagick

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-26 (fixed in 7.1.2-26)

Published 2026-07-01. Last modified 2026-07-29.